Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
736 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.34% | — | Lenovo BrowserAI | 17/7/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability was reported in the Lenovo Browser that could allow an attacker to obtain sensitive information if a user visits a web page with specially crafted content. | |
| Aplazada | Alta (8.4) | 0.16% | — | Lenovo Protection DriverAILenovo PC ManagerAILenovo BrowserAILenovo APP StoreAI | 17/7/2025 | 17/6/2026 | A buffer overflow vulnerability was reported in the Lenovo Protection Driver, prior to version 5.1.1110.4231, used in Lenovo PC Manager, Lenovo Browser, and Lenovo App Store could allow a local attacker with elevated privileges to execute arbitrary code. | |
| Analizada | Alta (7.7) | 0.38% | — | Filebrowser | 15/7/2025 | 17/6/2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.38.0, a Denial of Service (DoS) vulnerability exists in the file processing logic when reading a file on endpoint… | |
| Analizada | Alta (7.7) | 0.53% | — | Filebrowser | 15/7/2025 | 17/6/2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that remain valid even after the user logs out. As of time of publication, no known… | |
| Aplazada | Alta (8.6) | 0.29% | — | Digitware System Integration Corporation Cross-browser Document Creation ComponentAI | 14/7/2025 | 17/6/2026 | The cross-browser document creation component produced by Digitware System Integration Corporation has a Remote Code Execution vulnerability. If a user visits a malicious website while the component is active, remote attackers can cause the system to download and execute arbitrary programs. | |
| Aplazada | Media (6.5) | 0.45% | — | Asna RegistrarAIAsna Datagate FOR SQL ServerAIAsna Datagate Component SuiteAIAsna Datagate MonitorAI+13 | 3/7/2025 | 17/6/2026 | ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows system services that support license key management and deprecated Windows network authentication. The services are implemented with .NET remoting and can be exploited via well-known deserialization… | |
| Modificada | Alta (7.5) | 0.54% | — | Filebrowser | 30/6/2025 | 17/6/2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.34.1, a missing password policy and brute-force protection makes the authentication process insecure. Attackers could mount a brute-force attack to… | |
| Modificada | Media (4.3) | 0.39% | — | Filebrowser | 30/6/2025 | 17/6/2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In versions 2.32.0 and prior, the implementation of password protected links is error-prone, resulting in potential unprotected sharing of a file through a direct download… | |
| Analizada | Media (6.6) | 0.64% | — | Filebrowser | 30/6/2025 | 17/6/2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.33.10, the implementation of the allowlist is erroneous, allowing a user to execute more shell commands than they are authorized for. The concrete impact… | |
| Modificada | Media (6.5) | 0.60% | — | Filebrowser | 30/6/2025 | 17/6/2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.33.9, access tokens are used as GET parameters. The JSON Web Token (JWT) which is used as a session identifier will get leaked to anyone having access to… | |
| Analizada | Baja (3.9) | 0.13% | — | Debian Pycode-browser | 26/6/2025 | 17/6/2026 | pycode-browser before version 1.0 is prone to a predictable temporary file vulnerability. | |
| Modificada | Alta (8) | 1.1% | — | Filebrowser | 26/6/2025 | 17/6/2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In versions of the web application on the 2.x branch, all users have a scope assigned, and they only have access to the files within that scope. The Command Execution… | |
| Modificada | Alta (8) | 1.2% | — | Filebrowser | 26/6/2025 | 17/6/2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In versions on the 2.x branch prior to 2.33.10, the Command Execution feature of File Browser only allows the execution of shell command which have been predefined on a… | |
| Analizada | Alta (8.3) | 0.47% | — | Thebrowser ARC | 26/6/2025 | 17/6/2026 | Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when the user clicks anywhere on the website. | |
| Analizada | Media (5.4) | 0.33% | — | Filebrowser | 26/6/2025 | 17/6/2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. The Markdown preview function of File Browser prior to v2.33.7 is vulnerable to Stored Cross-Site-Scripting (XSS). Any JavaScript code that is part of a Markdown file… | |
| Analizada | Media (5.5) | 0.22% | — | Filebrowser | 26/6/2025 | 17/6/2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. The file access permissions for files uploaded to or created from File Browser are never explicitly set by the application. The same is true for the database used by File… | |
| Analizada | Media (5.3) | 0.58% | — | Steel Browser | 17/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Steel Browser up to 0.1.3. This affects the function handleFileUpload of the file api/src/modules/files/files.routes.ts. The manipulation of the argument filename leads to path traversal. It is possible to initiate the attack remotely. The patch is named… | |
| Aplazada | Media (5.1) | 0.19% | — | Paloaltonetworks Prisma Access BrowserAI | 12/6/2025 | 17/6/2026 | An insufficient implementation of cache vulnerability in Palo Alto Networks Prisma® Access Browser enables users to bypass certain data control policies. | |
| Analizada | Media (6.7) | 0.18% | — | Cisco FinesseCisco SocialminerCisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence Service+4 | 4/6/2025 | 17/6/2026 | A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. This vulnerability is due to improper validation of user-supplied command arguments. An… | |
| Analizada | Alta (7.4) | 0.37% | — | Yandex Browser | 30/5/2025 | 17/6/2026 | A use after free memory corruption issue exists in Yandex Browser for Desktop prior to version 24.4.0.682 | |
| Analizada | Media (6.9) | 0.44% | — | Yandex Browser | 21/5/2025 | 17/6/2026 | Yandex Browser for Android prior to version 21.3.0 allows remote attackers to perform IDN homograph attack. | |
| Analizada | Alta (8.3) | 0.79% | — | Yandex Browser | 21/5/2025 | 17/6/2026 | Yandex Browser Lite for Android prior to version 21.1.0 allows remote attackers to cause a denial of service. | |
| Analizada | Alta (8.2) | 0.54% | — | Yandex Browser | 21/5/2025 | 17/6/2026 | Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar. | |
| Aplazada | Media (4) | 0.45% | — | Browser-use Browser USEAI | 3/5/2025 | 17/6/2026 | In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority component. | |
| Analizada | Media (4.8) | 0.33% | — | Andrewhhan Browserpilot | 2/5/2025 | 17/6/2026 | A vulnerability was found in handrew browserpilot up to 0.2.51. It has been declared as critical. Affected by this vulnerability is the function GPTSeleniumAgent of the file browserpilot/browserpilot/agents/gpt_selenium_agent.py. The manipulation of the argument instructions leads to code injection. The attack needs… |